← Vulnerability feed

Vulnerability record · CVE-2012-1457 · published 21 March 2012

CVE-2012-1457: Antivirus TAR parser malware detection bypass via oversized length field

Aladdin · Esafe

The TAR file parser in numerous antivirus and anti-malware products mishandles a TAR archive entry whose length field exceeds the total TAR file size, allowing malware to evade detection. Because the flaw affects the scanning engine itself, a malicious archive can pass through the very control meant to catch it. The record notes it may later be split into multiple CVEs if the error is shown to occur independently across parsers.

4.3 CVSS 2.0 Medium EPSS 98% · top 0.1% CWE-264 · Permissions and access controls
4.3CVSS 2.0 base score
98%EPSS exploitation probability, 30 days
NoNot in CISA KEV
28Affected product versions listed by NVD
32References
16 Jun 2026Last modified by NVD

Description

The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, G Data AntiVirus 21, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, VBA32 3.12.14.2, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a TAR archive entry with a length field that exceeds the total TAR file size. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

medium priorityCVSS 2.0 base score is 4.3 (medium) with only integrity impact, but the flaw defeats malware detection across many widely deployed scanners and EPSS is extremely high.

What it is

The TAR file parser in numerous antivirus and anti-malware products mishandles a TAR archive entry whose length field exceeds the total TAR file size, allowing malware to evade detection. Because the flaw affects the scanning engine itself, a malicious archive can pass through the very control meant to catch it. The record notes it may later be split into multiple CVEs if the error is shown to occur independently across parsers.

Impact

An attacker gains the ability to deliver malware inside a crafted TAR archive that the affected scanner fails to flag, undermining the primary detection control. There is no reported confidentiality or availability impact; the effect is a bypass of malware detection.

Attack surface

Reached remotely over the network by submitting a crafted TAR archive to a system whose antivirus or anti-malware engine parses it. No authentication is required, but the CVSS vector indicates medium attack complexity and no user interaction is specified.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented. EPSS is very high (0.98331, 99.9th percentile), but the references carry no exploit tags, so active exploitation is not confirmed by this record.

What to do

  • Apply vendor updates for the affected antivirus/anti-malware engines; the record does not list fixed versions, so confirm with each vendor.
  • Where no fix is available, disable or restrict automatic scanning of untrusted TAR archives at the gateway and endpoint.
  • Block or quarantine inbound TAR archives at mail and web gateways until engines are confirmed patched.
  • Layer a second detection engine or sandbox that does not share the same TAR parser implementation.
  • Track the note that this CVE may be split; monitor vendor advisories for per-product identifiers and patches.

Detection

  • Hunt for TAR archives where an entry's declared length field exceeds the total file size.
  • Alert on TAR files passing through mail/web gateways that are subsequently executed or extracted on endpoints.
  • Correlate endpoint AV logs showing archives scanned without detection against later malware execution from the same file.
  • Monitor vendor advisories and engine version inventories to identify unpatched TAR parsers in the environment.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

28 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-1457 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2006-2869Alwil avast antivirus vulnerabilityUnspecified vulnerability in the CHM unpacker in avast! before 4.7.844 has unknown impact and remote attack vectors.EPSS 1.7%9.3CVE-2008-5528Aladdin esafe improper input validation vulnerabilityAladdin eSafe 7.0.17.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing …EPSS 5.4%9.3CVE-2007-2917Authentium command antivirus vulnerabilityMultiple buffer overflows in a certain ActiveX control in odapi.dll in Authentium Command Antivirus before 4.93.8 allow remote attackers to execute a…EPSS 6.6%7.5CVE-2006-4626Alwil avast antivirus vulnerabilityHeap-based buffer overflow in alwil avast! Anti-virus Engine before 4.7.869 allows remote attackers to execute arbitrary code via a crafted LHA file …EPSS 4.7%7.5CVE-2005-2385Alwil avast antivirus vulnerabilityBuffer overflow in a third-party compression library (UNACEV2.DLL), as used in avast! Antivirus Home/Professional Edition 4.6.665 and Server Edition …EPSS 4.0%7.5CVE-2005-1719Alwil avast antivirus vulnerabilityUnknown vulnerability in ALWIL avast! antivirus 4 (4.6.6230) and earlier, when running on Windows NT 4.0, does not properly detect certain viruses.EPSS 1.4%7.2CVE-2006-1355Alwil avast antivirus vulnerabilityavast! Antivirus 4.6.763 and earlier sets "BUILTIN\Everyone" permissions to critical system files in the installation folder, which allows local user…EPSS 0.39%7.2CVE-2005-1770Alwil avast antivirus memory buffer overflow vulnerabilityBuffer overflow in the Aavmker4 device driver in Avast! Antivirus 4.6 and possibly other versions allows local users to cause a denial of service (sy…EPSS 0.68%

Source: NIST National Vulnerability Database (record CVE-2012-1457), CISA KEV, FIRST EPSS (scores of 2026-09-23). This page is refreshed as NVD updates the record.